Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
SAFEPAY | No | 2026-04-28T07:26:21 |
nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion
|
|||
|
|
SAFEPAY | No | 2026-04-28T07:28:54 |
cqkrkmmivhakl3fwgxscurduu3znmroablt7jskxszkctixyseij5gad.onion
|
|||
|
|
No | 2026-04-28T07:31:16 |
nj5qix45sxnl4h4og6hcgwengg2oqloj3c2rhc6dpwiofx3jbivcs6qd.onion
|
||||
|
|
SAFEPAY | No | 2026-04-28T07:33:23 |
j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion
|
|||
|
|
Safepay Blog | Yes | 2026-05-15T05:39:20 | nginx |
safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
Invoke-ShareFinder
|
|
|
|
|
|
CMSTPLUA
Regsvr32.exe
dllhost.exe
|
7-Zip
WinRAR
|
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Windows Management Instrumentation | Valid Accounts | Valid Accounts | Disable or Modify Tools | OS Credential Dumping | Domain Trust Discovery | Remote Services | Archive Collected Data | Exfiltration Over Web Service | Data Encrypted for Impact |
| Command and Scripting Interpreter | Inhibit System Recovery |